Cybersecurity company Kaspersky said a newly identified malware framework is targeting cryptocurrency investors through social engineering tactics and trojanized GitHub apps. Kaspersky has uncovered a new malware framework targeting cryptocurrency investors. Dubbed “OkoBot,” the malware initiates an infection chain that starts with social engineering tactics such as ClickFix, which tricks users into running malicious commands, or trojanized GitHub apps that deliver a backdoor to infected devices, the cybersecurity company wrote in a Wednesday report. The malware can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets. Kaspersky said it identified multiple attacks involving this malware family since January 2026. Read more
Kaspersky found a new malware, dubbed Stealka, that disguises itself as game mods and pirated software to steal crypto wallets, passwords, and browser data. New malware has been discovered that targets crypto wallets and browser extensions while disguising itself as game cheats and mods, said cybersecurity firm Kaspersky. Kaspersky reported on Thursday that it had uncovered a new infostealer dubbed “Stealka,” which targets Microsoft Windows user data. Attackers have used the malware, which was discovered in November, to hijack accounts, steal cryptocurrency, and install crypto miners on their victims’ computers while masquerading as video game cracks, cheats, and mods. Read more